← All CVEs NewScan detects
critical

CVE-2023-6553

Backup Migration unauthenticated remote code execution through attacker-controlled includes in backup-heart.php

Severity
critical
Affected product
backup-backup
Affected versions
backup-backup ≤ 1.3.7
Fixed in
backup-backup 1.3.8
Added to NewScan
2026-09-09
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints backup-backup from its response and reports this CVE when the detected version falls inside the affected range below.

The WordPress plugin slug is backup-backup. CVE-2023-6553 affects every release through 1.3.7 and is fixed in 1.3.8; unauthenticated callers control paths consumed by includes/backup-heart.php and can reach PHP execution. scan_wordpress probes this readme only after WordPress is confirmed, and records the advisory only when its Stable tag is inside the affected range. Version-match only: actively proving the issue would execute PHP on the customer's server.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →